I've been playing around with firebase multi-provider logins. I enabled both email and google.
I've read somewhere that if the email is not yet verified and a user tries to login using google then the user account will be overridden albeit with the same user id.
The reason for this is gmail is a trusted provider and Firebase unlinks the previous unverified email and overrides the data with google user data.
Based from what i've read from this comment, this is a security feature of Firebase and expected behavior.
My question is how do i handle such scenario when a user has been using his account with email and password and all of a sudden if a user logged in using gmail then he'll no longer be able to login using email and password.
Yes, the user can just simply login using google login and is still the same user account and simply was overridden by google but some users may think this is a bug and not a good user experience.